Attack Trees for Security and Privacy in Social Virtual Reality Learning Environments

11/08/2019
by   Samaikya Valluripally, et al.
0

Social Virtual Reality Learning Environment (VRLE) is a novel edge computing platform for collaboration amongst distributed users. Given that VRLEs are used for critical applications (e.g., special education, public safety training), it is important to ensure security and privacy issues. In this paper, we present a novel framework to obtain quantitative assessments of threats and vulnerabilities for VRLEs. Based on the use cases from an actual social VRLE viz., vSocial, we first model the security and privacy using the attack trees. Subsequently, these attack trees are converted into stochastic timed automata representations that allow for rigorous statistical model checking. Such an analysis helps us adopt pertinent design principles such as hardening, diversity and principle of least privilege to enhance the resilience of social VRLEs. Through experiments in a vSocial case study, we demonstrate the effectiveness of our attack tree modeling with a reduction of 26 probability of loss of integrity (security) and 80 (privacy) in before and after scenarios pertaining to the adoption of the design principles.

READ FULL TEXT
research
11/29/2018

Security, Privacy and Safety Risk Assessment for Virtual Reality Learning Environment Applications

Social Virtual Reality based Learning Environments (VRLEs) such as vSoci...
research
08/27/2021

Rule-based Adaptations to Control Cybersickness in Social Virtual Reality Learning Environments

Social virtual reality learning environments (VRLEs) provide immersive e...
research
12/16/2021

Ubiq: A System to Build Flexible Social Virtual Reality Experiences

While they have long been a subject of academic study, social virtual re...
research
01/21/2021

Quantitative Security Risk Modeling and Analysis with RisQFLan

Domain-specific quantitative modeling and analysis approaches are fundam...
research
04/23/2023

Privacy Computing Meets Metaverse: Necessity, Taxonomy and Challenges

Metaverse, the core of the next-generation Internet, is a computer-gener...
research
05/10/2022

Improving Emergency Training for Earthquakes Through Immersive Virtual Environments and Anxiety Tests: A Case Study

Because of the occurrence of severe and large magnitude earthquakes each...
research
11/19/2021

UEFI virtual machine firmware hardening through snapshots and attack surface reduction

The Unified Extensible Firmware Interface (UEFI) is a standardised inter...

Please sign up or login with your details

Forgot password? Click here to reset